W3C home > Mailing lists > Public > public-webapps@w3.org > October to December 2009

Re: [WARP] Comments to WARP spec

From: Robin Berjon <robin@berjon.com>
Date: Wed, 18 Nov 2009 12:56:39 +0100
Cc: Marcos Caceres <marcosc@opera.com>, "SULLIVAN, BRYAN L (ATTCINW)" <BS3131@att.com>, WebApps WG <public-webapps@w3.org>
Message-Id: <FC2BF689-6C4C-484F-AAD0-BB542788FDD7@berjon.com>
To: Marcin Hanclik <Marcin.Hanclik@access-company.com>
On Nov 12, 2009, at 16:36 , Marcin Hanclik wrote:
> I understand that too many details may not work or be an obstacle in the adoption.
> However, I derive that from the security point of view we still would like to distinguish at least between executable and non-executable content.

That doesn't work. Not only could some script just manipulate canvas stuff, but some images can execute script. It would be trivial to create lossless bitmaps that could encode script. One could also use XHR to evaluate content returned as text/plain (or as a bunch of other things). One could request an image that is redirected to http://address/of/image?put+a+complete+script+here and then evaluate the query.

I think there are two threads in this discussion, one seems to concern the default behaviour of widget UAs as defined by WARP  I think that's a valuable discussion to have (is the request simply that WARP be open by default for the same things that are allowed in a browser?) that is being drowned in the other discussion, which is about a semi-sentient local filtering proxy firewall built using pieces of flint and some string. Can we focus on the first one?

Robin Berjon - http://berjon.com/
Received on Wednesday, 18 November 2009 11:57:09 UTC

This archive was generated by hypermail 2.3.1 : Friday, 27 October 2017 07:26:20 UTC